HackingVulnerability ExploitSupply Chain (3P Vendor)TargetedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
American National Insurance Company
bd_ec60be18372f43ac · schema v1 · pii pii-v1
Full breach record for American National Insurance Company →American National Insurance Company notified Hawaii residents of a cybersecurity incident involving a vulnerability in the third-party MOVEit Transfer application (Progress Software). Unauthorized access occurred on May 28, 2023, exposing personal information including names, SSNs, DOBs, and addresses. The company took the system offline, engaged forensic advisors, and offered two years of credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://cca.hawaii.gov/wp-content/uploads/2026/05/Letter.2023-0985.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 7, 2023
- Raw hash
- 9f2dcc064369652d6756350c855ad82a285dbf62456cc9467f11735afd5cf8d1
Reporting entity
- Name
- AMERICAN NATIONAL GROUP INC.norm: american national
Victim entity
- Name
- American National Insurance Companynorm: american national insurance
Incident
- Discovered
- May 28, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement and is cooperating with their investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 10 weeks(71 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.